🍎🗒️ New macOS persistence blog post. 🎉
➡️ Persist through the NVRAM - The 'apple-trusted-trampoline'
Meet the rc.trampoline launchd 🚀 boot task.
https://t.co/VM0Bdepj8I
Official WinDBG TTD Live Recording API has arrived. Load TTDLiveRecorder.dll and call APIs from within the traced process. Add custom metadata and events. The docs aren't really indexed, well, here's a link to the interface docs for the LiveRecorder
https://t.co/qZABrkemka
@HackingDave Mission accomplished! After 10 years it is still inflicting pain 🤣 … kidding apart those were good times for real, we had so much fun and learned so much at the same time. I certainly miss it
I’m so thankful and blessed at the folks we have working at #TrustedSec and our ability to teach others and share our experiences.
Best team ever. Many of these folks have been at TS 9, 10, and 11 years which is so cool.
I started teaching at Blackhat I think in 2008 or 2009 but have been going since 2003 and it’s been such a huge part of my life since I started my career. It’s so cool to teach others and be part of their development and success in this industry.
One of my fondest memories is Ryujin destroying my mind and soul in the advanced windows exploitation class
and @int0x80 beating me on each challenge 😂 Dave’s a badass.
As always, a great post by @standa_t . Super clear and informative with demos of data remapping and mitigating it through HLAT.
Hope to see Hyper-V enable it soon
Pleased to announce that the materials of Hypervisor 101 in Rust🦀is now public!
A one-day long course taught at #gccsec, to quickly learn hardware-assisted virtualization technology and its application for high-performance fuzzing on Intel/AMD processors
https://t.co/ywRR63pDFd
The full paper is now published at ACM TOSEM
https://t.co/rb4ncqjv4x
Artifacts at https://t.co/GtC5hM12Yn
This is one of the first papers in the community that passed through a process of preregistration, more info at https://t.co/JNnAAmFa8q
Registration for my hypervisor development class at #OffensiveCon23 is open!
If you are interested in reading, writing or reversing hypervisors, or just low-level⚙️technologies in general, this class will be a fun and great opportunity to gain a solid understanding
StealthHook - A method for hooking functions without modifying memory protection.
This tool automatically discovers writable global pointers/vtable entries that are nested within the target function, enabling stealthy function hooking and interception.
https://t.co/vdrNVTdMnd